UbuntuUpdates.org

Package "util-linux"

Name: util-linux

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • interactive login tools

Latest version: 2.39.3-9ubuntu6.6
Release: noble (24.04)
Level: security
Repository: universe

Links



Other versions of "util-linux" in Noble

Repository Area Version
base universe 2.39.3-9ubuntu6
base main 2.39.3-9ubuntu6
security main 2.39.3-9ubuntu6.6
updates main 2.39.3-9ubuntu6.6
updates universe 2.39.3-9ubuntu6.6

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.39.3-9ubuntu6.6 2026-08-31 14:07:49 UTC

util-linux (2.39.3-9ubuntu6.6) noble-security; urgency=medium

  * SECURITY UPDATE: Heap use-after-free via crafted block device image
    - debian/patches/CVE-2026-13595.patch: libblkid: fix use-after-free in
      nested partition probing in libblkid/src/partitions/partitions.c.
    - CVE-2026-13595
  * SECURITY UPDATE: TOCTOU in mount utility
    - debian/patches/CVE-2026-27456.patch: loopdev: add LOOPDEV_FL_NOFOLLOW to
      prevent symlink attacks in include/loopdev.h, lib/loopdev.c,
      libmount/src/hook_loopdev.c.
    - CVE-2026-27456
  * SECURITY UPDATE: Local Privilege Escalation via TOCTOU in mount
    - debian/patches/CVE-2026-53612.patch: libmount: use fd-based fchownat/chmod
      in hook_owner in libmount/src/hook_owner.c.
    - CVE-2026-53612
  * SECURITY UPDATE: Another local Privilege Escalation via TOCTOU in mount
    - debian/patches/CVE-2026-53613-pre1.patch: lib/fileutils: add
      ul_open_no_symlinks() in configure.ac, include/fileutils.h,
      lib/fileutils.c, meson.build.
    - debian/patches/CVE-2026-53613.patch: libmount: add fd_target to context
      for TOCTOU prevention in libmount/src/context.c,
      libmount/src/context_mount.c, libmount/src/hook_mount.c,
      libmount/src/hook_mount_legacy.c, libmount/src/mountP.h.
    - CVE-2026-53613
  * SECURITY UPDATE: Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2
    Environment Variable
    - debian/patches/CVE-2026-53614.patch: libmount: fix SUID bypass via
      LIBMOUNT_FORCE_MOUNT2 and legacy mount path in libmount/src/hook_mount.c,
      libmount/src/hook_mount_legacy.c.
    - CVE-2026-53614
  * SECURITY UPDATE: Integer Overflow or Wraparound in dos.c
    - debian/patches/CVE-2026-53615.patch: libblkid: dos: validate EBR data and
      links within extended partition in libblkid/src/partitions/dos.c.
    - CVE-2026-53615

 -- Marc Deslauriers Wed, 19 Aug 2026 12:47:51 -0400

Source diff to previous version
CVE-2026-13595 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers
CVE-2026-27456 util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified
CVE-2026-53612 Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown
CVE-2026-53613 Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection
CVE-2026-53614 Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8)
CVE-2026-53615 Integer Overflow or Wraparound in libblkid/src/partitions/dos.c

Version: 2.39.3-9ubuntu6.5 2026-03-12 23:09:57 UTC

  util-linux (2.39.3-9ubuntu6.5) noble-security; urgency=medium

  * d/p/ubuntu/su-pty-drop-caps.patch: harden 'su --pty' to temporarily lower
    capabilities while proxying between stdin/stdout and the pty master. This
    is to avoid su from being used to exploit kernel vulnerabilities.

 -- Luci Stanescu <email address hidden> Fri, 06 Mar 2026 18:00:54 +0200




About   -   Send Feedback to @ubuntu_updates